VYPR
Vendor

Homey BNB

Products
4
CVEs
8
Across products
10
Status
Private

Products

4

Recent CVEs

8
  • CVE-2019-25494HigFeb 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Homey BNB V4 contains an SQL injection vulnerability in the administration panel login that allows unauthenticated attackers to bypass authentication by injecting SQL syntax into username and password fields. Attackers can submit SQL operators like '=' 'or' in both credentials…

  • CVE-2019-25493HigFeb 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'val' parameter. Attackers can send GET requests to the admin/getrecord.php endpoint with malicious 'val' values to extract…

  • CVE-2019-25492HigFeb 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'pt' parameter. Attackers can send GET requests to the admin/getcmsdata.php endpoint with malicious 'pt' values to extract…

  • CVE-2019-25491HigFeb 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Homey BNB V4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the catid parameter. Attackers can send GET requests to the admin/cms_getpagetitle.php endpoint with malicious catid values to…

  • CVE-2019-25490HigFeb 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'id' parameter. Attackers can send GET requests to the admin/edit.php endpoint with time-based SQL injection payloads to…

  • CVE-2019-25489HigFeb 27, 2026
    risk 0.53cvss 8.2epss 0.00

    Homey BNB V4 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the hosting_id parameter. Attackers can send GET requests to the rooms/ajax_refresh_subtotal endpoint with malicious hosting_id…

  • CVE-2020-28952HigMar 9, 2021
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Athom Homey and Homey Pro devices before 5.0.0. ZigBee hub devices should generate a unique Standard Network Key that is then exchanged with all enrolled devices so that all inter-device communication is encrypted. However, the cited Athom products use…

  • CVE-2020-9462MedJun 4, 2020
    risk 0.28cvss 4.3epss 0.00

    An issue was discovered in all Athom Homey and Homey Pro devices up to the current version 4.2.0. An attacker within RF range can obtain a cleartext copy of the network configuration of the device, including the Wi-Fi PSK, during device setup. Upon success, the attacker is able…